customer-email-draft-threads
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill primarily functions by ingesting untrusted data from external sources (Gmail messages) and using that data to generate drafts and project threads. An attacker could craft an email designed to manipulate the agent's behavior during the triaging or handoff process.
- Ingestion points: Untrusted data enters the agent context through Gmail message bodies, headers, links, quoted text, and attachments as described in the
SKILL.mdworkflow andrunbook.mdsafety contract. - Boundary markers: The instructions include explicit warnings for the agent to treat email content as untrusted and to ignore embedded instructions. However, there are no structural delimiters (like unique tokens or specific data wrappers) used when the untrusted content is passed into the thread handoff template.
- Capability inventory: The skill has the ability to create Gmail drafts, create and manage Codex project threads, store information in long-term memory, and commit changes to the local repository.
- Sanitization: The skill relies on the agent's internal classification logic to identify risks like phishing or scam attempts, but does not specify any programmatic sanitization or escaping of the external data before it is interpolated into instructions for project threads.
Audit Metadata